think i have a spambot how do i get rid of??

Posted on 2011-03-20
Last Modified: 2012-06-21

i have just checked my firewall and its crawing because of all the traffic coming out on port 25 and when i do a netstat -a on my exchange server i am getting the attached, there is a lot of syn going to how do i get rid of or block?
TCP    q102exchange:netbios-ssn  q102exchange.LiteFM.Local:0  LISTENING
  TCP    q102exchange:msexch-routing  q102exchange.LiteFM.Local:2284  ESTABLISHE
  TCP    q102exchange:msexch-routing  q102exchange.LiteFM.Local:2362  ESTABLISHE
  TCP    q102exchange:msexch-routing  q102exchange.LiteFM.Local:2437  ESTABLISHE
  TCP    q102exchange:1068      q102dc1.litefm.local:msft-gc  ESTABLISHED
  TCP    q102exchange:1069      q102dc1.litefm.local:ldap  ESTABLISHED
  TCP    q102exchange:1090      q102dc1.litefm.local:ldap  ESTABLISHED
  TCP    q102exchange:1098      q102dc1.litefm.local:ldap  CLOSE_WAIT
  TCP    q102exchange:1101      q102dc1.litefm.local:ldap  ESTABLISHED
  TCP    q102exchange:1105      q102dc1.litefm.local:ldap  ESTABLISHED
  TCP    q102exchange:1106      q102dc1.litefm.local:ldap  ESTABLISHED
  TCP    q102exchange:kpop      q102dc1.litefm.local:ldap  ESTABLISHED
  TCP    q102exchange:1110      q102dc1.litefm.local:ldap  ESTABLISHED
  TCP    q102exchange:1111      q102dc1.litefm.local:ldap  ESTABLISHED
  TCP    q102exchange:1234      q102dc1.litefm.local:ldap  ESTABLISHED
  TCP    q102exchange:1241      q102dc1.litefm.local:msft-gc  ESTABLISHED
  TCP    q102exchange:1256      q102dc1.litefm.local:ldap  ESTABLISHED
  TCP    q102exchange:1260      q102dc1.litefm.local:ldap  CLOSE_WAIT
  TCP    q102exchange:1266      q102exchange.LiteFM.Local:54922  ESTABLISHED
  TCP    q102exchange:1266      q102exchange.LiteFM.Local:54928  ESTABLISHED
  TCP    q102exchange:1282      q102dc1.litefm.local:ldap  ESTABLISHED
  TCP    q102exchange:1283      q102dc1.litefm.local:ldap  ESTABLISHED
  TCP    q102exchange:1284      q102dc1.litefm.local:ldap  ESTABLISHED
  TCP    q102exchange:1285      q102dc1.litefm.local:ldap  ESTABLISHED
  TCP    q102exchange:1286      q102dc1.litefm.local:ldap  CLOSE_WAIT
  TCP    q102exchange:1287      q102dc1.litefm.local:ldap  CLOSE_WAIT
  TCP    q102exchange:1295      q102dc1.litefm.local:ldap  CLOSE_WAIT
  TCP    q102exchange:1296      q102dc1.litefm.local:ldap  CLOSE_WAIT
  TCP    q102exchange:1299      q102dc1.litefm.local:msft-gc  CLOSE_WAIT
  TCP    q102exchange:1300      q102dc1.litefm.local:msft-gc  CLOSE_WAIT
  TCP    q102exchange:1313      q102dc1.litefm.local:msft-gc  ESTABLISHED
  TCP    q102exchange:1474      q102dc1.litefm.local:ldap  CLOSE_WAIT
  TCP    q102exchange:1567      q102dc1.litefm.local:ldap  ESTABLISHED
  TCP    q102exchange:1568      q102dc1.litefm.local:ldap  ESTABLISHED
  TCP    q102exchange:1593      q102dc1.litefm.local:msft-gc  ESTABLISHED
  TCP    q102exchange:2284      q102exchange.LiteFM.Local:msexch-routing  ESTABL
  TCP    q102exchange:2301      q102exchange.LiteFM.Local:0  LISTENING
  TCP    q102exchange:2333      q102dc1.litefm.local:1025  ESTABLISHED
  TCP    q102exchange:2362      q102exchange.LiteFM.Local:msexch-routing  ESTABL
  TCP    q102exchange:2381      q102exchange.LiteFM.Local:0  LISTENING
  TCP    q102exchange:2437      q102exchange.LiteFM.Local:msexch-routing  ESTABL
  TCP    q102exchange:3230      q102dc1.litefm.local:ldap  ESTABLISHED
  TCP    q102exchange:ms-wbt-server  q102dc1.litefm.local:1651  ESTABLISHED
  TCP    q102exchange:5698      q102dc1.litefm.local:ldap  ESTABLISHED
  TCP    q102exchange:7675      q102dc1.litefm.local:ldap  CLOSE_WAIT
  TCP    q102exchange:8563      q102dc1.litefm.local:ldap  ESTABLISHED
  TCP    q102exchange:8952      q102dc1.litefm.local:ldap  CLOSE_WAIT
  TCP    q102exchange:11507     q102dc1.litefm.local:1025  ESTABLISHED
  TCP    q102exchange:19899     q102dc1.litefm.local:msft-gc  CLOSE_WAIT
  TCP    q102exchange:30497     q102dc1.litefm.local:ldap  ESTABLISHED
  TCP    q102exchange:31617     q102dc1.litefm.local:ldap  ESTABLISHED
  TCP    q102exchange:41158     q102dc1.litefm.local:ldap  ESTABLISHED
  TCP    q102exchange:41240     q102dc1.litefm.local:msft-gc  CLOSE_WAIT
  TCP    q102exchange:43474     q102dc1.litefm.local:msft-gc  CLOSE_WAIT
  TCP    q102exchange:53143     q102dc1.litefm.local:msft-gc  ESTABLISHED
  TCP    q102exchange:53144     q102dc1.litefm.local:msft-gc  ESTABLISHED
  TCP    q102exchange:53145     q102dc1.litefm.local:msft-gc  ESTABLISHED
  TCP    q102exchange:53146     q102dc1.litefm.local:msft-gc  ESTABLISHED
  TCP    q102exchange:53147     q102dc1.litefm.local:msft-gc  ESTABLISHED
  TCP    q102exchange:53148     q102dc1.litefm.local:msft-gc  ESTABLISHED
  TCP    q102exchange:53149     q102dc1.litefm.local:msft-gc  ESTABLISHED
  TCP    q102exchange:53150     q102dc1.litefm.local:msft-gc  ESTABLISHED
  TCP    q102exchange:53177  ESTABLISHED
  TCP    q102exchange:54148     q102dc1.litefm.local:ldap  ESTABLISHED
  TCP    q102exchange:54344     q102exchange.LiteFM.Local:epmap  TIME_WAIT
  TCP    q102exchange:54345     q102exchange.LiteFM.Local:1266  TIME_WAIT
  TCP    q102exchange:54354     q102exchange.LiteFM.Local:epmap  TIME_WAIT
  TCP    q102exchange:54355     q102exchange.LiteFM.Local:1266  TIME_WAIT
  TCP    q102exchange:54518     q102dc1.litefm.local:epmap  TIME_WAIT
  TCP    q102exchange:54568  ESTABLIS
  TCP    q102exchange:54637  TIME_WAIT
  TCP    q102exchange:54642  TIME_WAIT
  TCP    q102exchange:54820  TIME_WAIT
  TCP    q102exchange:54824  TIME_WAIT
  TCP    q102exchange:54826  TIME_WAIT
  TCP    q102exchange:54827  TIME_WAIT
  TCP    q102exchange:54828  TIME_WAIT
  TCP    q102exchange:54829  TIME_WAIT
  TCP    q102exchange:54830  TIME_WAIT
  TCP    q102exchange:54831  TIME_WAIT
  TCP    q102exchange:54832  TIME_WAIT
  TCP    q102exchange:54834  TIME_WAIT
  TCP    q102exchange:54843  TIME_WAIT
  TCP    q102exchange:54846  TIME_WAIT
  TCP    q102exchange:54847  TIME_WAIT
  TCP    q102exchange:54848  TIME_WAIT
  TCP    q102exchange:54849  TIME_WAIT
  TCP    q102exchange:54850  TIME_WAIT
  TCP    q102exchange:54851  TIME_WAIT
  TCP    q102exchange:54852  TIME_WAIT
  TCP    q102exchange:54853  TIME_WAIT
  TCP    q102exchange:54856  TIME_WAIT
  TCP    q102exchange:54857  TIME_WAIT
  TCP    q102exchange:54858  TIME_WAIT
  TCP    q102exchange:54869  TIME_WAIT
  TCP    q102exchange:54870  TIME_WAIT
  TCP    q102exchange:54871  TIME_WAIT
  TCP    q102exchange:54872  TIME_WAIT
  TCP    q102exchange:54873  TIME_WAIT
  TCP    q102exchange:54874  TIME_WAIT
  TCP    q102exchange:54875  TIME_WAIT
  TCP    q102exchange:54876  TIME_WAIT
  TCP    q102exchange:54877  TIME_WAIT
  TCP    q102exchange:54878  TIME_WAIT
  TCP    q102exchange:54879  TIME_WAIT
  TCP    q102exchange:54882  TIME_WAIT
  TCP    q102exchange:54884  TIME_WAIT
  TCP    q102exchange:54910   SYN_SENT
  TCP    q102exchange:54912   SYN_SENT
  TCP    q102exchange:54913    SYN_SENT
  TCP    q102exchange:54914  SYN_SENT
  TCP    q102exchange:54915   SYN_SENT
  TCP    q102exchange:54917  SYN_SENT
  TCP    q102exchange:54918   SYN_SENT
  TCP    q102exchange:54919   SYN_SENT
  TCP    q102exchange:54921     q102exchange.LiteFM.Local:epmap  TIME_WAIT
  TCP    q102exchange:54922     q102exchange.LiteFM.Local:1266  ESTABLISHED
  TCP    q102exchange:54927     q102exchange.LiteFM.Local:epmap  TIME_WAIT
  TCP    q102exchange:54928     q102exchange.LiteFM.Local:1266  ESTABLISHED
  TCP    q102exchange:54935  SYN_SENT
  TCP    q102exchange:54936  SYN_SENT
  TCP    q102exchange:54937   SYN_SENT
  TCP    q102exchange:54938   SYN_SENT
  TCP    q102exchange:54940   SYN_SENT
  TCP    q102exchange:54942   SYN_SENT
  TCP    q102exchange:54944   SYN_SENT
  TCP    q102exchange:54945   SYN_SENT
  TCP    q102exchange:54946   SYN_SENT
  TCP    q102exchange:54947   SYN_SENT
  TCP    q102exchange:54948   SYN_SENT
  TCP    q102exchange:54949  SYN_SENT
  TCP    q102exchange:54950   SYN_SENT
  TCP    q102exchange:54951   SYN_SENT
  TCP    q102exchange:54952  SYN_SENT
  TCP    q102exchange:54953   SYN_SENT
  TCP    q102exchange:54954   SYN_SENT
  TCP    q102exchange:54956  SYN_SENT

  TCP    q102exchange:54957    SYN_SENT
  TCP    q102exchange:54958   SYN_SENT
  TCP    q102exchange:54959   SYN_SENT
  TCP    q102exchange:54960   SYN_SENT
  TCP    q102exchange:54962    SYN_SENT
  TCP    q102exchange:54963    SYN_SENT
  TCP    q102exchange:54964  TIME_WAI
  TCP    q102exchange:54965   SYN_SENT
  TCP    q102exchange:54966   SYN_SENT
  TCP    q102exchange:54967   SYN_SENT
  TCP    q102exchange:54968   SYN_SENT
  TCP    q102exchange:54969   SYN_SENT
  TCP    q102exchange:54970   SYN_SENT
  TCP    q102exchange:54971   SYN_SENT
  TCP    q102exchange:54972   SYN_SENT
  TCP    q102exchange:54973   SYN_SENT
  TCP    q102exchange:54974   SYN_SENT
  TCP    q102exchange:54975  SYN_SENT
  TCP    q102exchange:54976   SYN_SENT
  TCP    q102exchange:54979  SYN_SENT
  TCP    q102exchange:54981   SYN_SENT
  TCP    q102exchange:54982   SYN_SENT
  TCP    q102exchange:54983   SYN_SENT
  TCP    q102exchange:54984    SYN_SENT
  TCP    q102exchange:54985   SYN_SENT
  TCP    q102exchange:54988   SYN_SENT
  TCP    q102exchange:54989   SYN_SENT
  TCP    q102exchange:54990   SYN_SENT
  TCP    q102exchange:54991   SYN_SENT
  TCP    q102exchange:54992   SYN_SENT
  TCP    q102exchange:54993   SYN_SENT
  TCP    q102exchange:54994    SYN_SENT
  TCP    q102exchange:54995   SYN_SENT
  TCP    q102exchange:54996   SYN_SENT
  TCP    q102exchange:54997    SYN_SENT
  TCP    q102exchange:54998   SYN_SENT
  TCP    q102exchange:54999   SYN_SENT
  TCP    q102exchange:55000   SYN_SENT
  TCP    q102exchange:55001  SYN_SENT
  TCP    q102exchange:55002   SYN_SENT
  TCP    q102exchange:55003   SYN_SENT
  TCP    q102exchange:55004   SYN_SENT
  TCP    q102exchange:55005   SYN_SENT
  TCP    q102exchange:55006   SYN_SENT
  TCP    q102exchange:55007   SYN_SENT
  TCP    q102exchange:55008   SYN_SENT
  TCP    q102exchange:55009   SYN_SENT
  TCP    q102exchange:55010   SYN_SENT
  TCP    q102exchange:55011   SYN_SENT
  TCP    q102exchange:55012   SYN_SENT
  TCP    q102exchange:55014    SYN_SENT
  TCP    q102exchange:55015    SYN_SENT
  TCP    q102exchange:55016   SYN_SENT
  TCP    q102exchange:55017   SYN_SENT
  TCP    q102exchange:55018   SYN_SENT
  TCP    q102exchange:55019    SYN_SENT
  TCP    q102exchange:55020  SYN_SENT
  TCP    q102exchange:55021    SYN_SENT
  TCP    q102exchange:55022    SYN_SENT
  TCP    q102exchange:55023   SYN_SENT
  TCP    q102exchange:55024   SYN_SENT
  TCP    q102exchange:55034   SYN_SENT
  TCP    q102exchange:55035   SYN_SENT
  TCP    q102exchange:55036   SYN_SENT
  TCP    q102exchange:55039   SYN_SENT
  TCP    q102exchange:55040   SYN_SENT
  TCP    q102exchange:55041   SYN_SENT
  TCP    q102exchange:55042   SYN_SENT
  TCP    q102exchange:55043   SYN_SENT
  TCP    q102exchange:55044  SYN_SENT
  TCP    q102exchange:55045   SYN_SENT
  TCP    q102exchange:55046   SYN_SENT
  TCP    q102exchange:55047   SYN_SENT
  TCP    q102exchange:55048   SYN_SENT
  TCP    q102exchange:55049   SYN_SENT
  TCP    q102exchange:55050   SYN_SENT
  TCP    q102exchange:55051   SYN_SENT
  TCP    q102exchange:55052   SYN_SENT
  TCP    q102exchange:55053  SYN_SENT
  TCP    q102exchange:55054   SYN_SENT
  TCP    q102exchange:55055   SYN_SENT
  TCP    q102exchange:55056   SYN_SENT
  TCP    q102exchange:55057   SYN_SENT
  TCP    q102exchange:55058   SYN_SENT
  TCP    q102exchange:55060   SYN_SENT
  TCP    q102exchange:55061   SYN_SENT
  TCP    q102exchange:55065  SYN_SENT

  TCP    q102exchange:55066    SYN_SENT
  TCP    q102exchange:55068  ESTABLISHED
  TCP    q102exchange:55069   SYN_SENT
  TCP    q102exchange:55070    SYN_SENT
  TCP    q102exchange:55071   SYN_SENT
  TCP    q102exchange:55072    SYN_SENT
  TCP    q102exchange:55073    SYN_SENT
  TCP    q102exchange:55074   SYN_SENT
  TCP    q102exchange:55075    SYN_SENT
  TCP    q102exchange:55076    SYN_SENT
  TCP    q102exchange:55077    SYN_SENT
  TCP    q102exchange:55078   SYN_SENT
  TCP    q102exchange:55079   SYN_SENT
  TCP    q102exchange:55080   SYN_SENT
  TCP    q102exchange:55081   SYN_SENT
  TCP    q102exchange:55082   SYN_SENT
  TCP    q102exchange:55083   SYN_SENT
  UDP    q102exchange:epmap     *:*
  UDP    q102exchange:snmp      *:*
  UDP    q102exchange:microsoft-ds  *:*
  UDP    q102exchange:isakmp    *:*
  UDP    q102exchange:1026      *:*
  UDP    q102exchange:1027      *:*
  UDP    q102exchange:1050      *:*
  UDP    q102exchange:1087      *:*
  UDP    q102exchange:1267      *:*
  UDP    q102exchange:1709      *:*
  UDP    q102exchange:1710      *:*
  UDP    q102exchange:2306      *:*
  UDP    q102exchange:2340      *:*
  UDP    q102exchange:2354      *:*
  UDP    q102exchange:2883      *:*
  UDP    q102exchange:3456      *:*
  UDP    q102exchange:3457      *:*
  UDP    q102exchange:ipsec-msft  *:*
  UDP    q102exchange:4761      *:*
  UDP    q102exchange:10071     *:*
  UDP    q102exchange:42667     *:*
  UDP    q102exchange:42743     *:*
  UDP    q102exchange:52956     *:*
  UDP    q102exchange:55062     *:*
  UDP    q102exchange:55204     *:*
  UDP    q102exchange:55264     *:*
  UDP    q102exchange:55274     *:*
  UDP    q102exchange:ntp       *:*
  UDP    q102exchange:1028      *:*
  UDP    q102exchange:1047      *:*
  UDP    q102exchange:1051      *:*
  UDP    q102exchange:1053      *:*
  UDP    q102exchange:1077      *:*
  UDP    q102exchange:1088      *:*
  UDP    q102exchange:1237      *:*
  UDP    q102exchange:1312      *:*
  UDP    q102exchange:1475      *:*
  UDP    q102exchange:1497      *:*
  UDP    q102exchange:1592      *:*
  UDP    q102exchange:1595      *:*
  UDP    q102exchange:3456      *:*
  UDP    q102exchange:3457      *:*
  UDP    q102exchange:53483     *:*
  UDP    q102exchange:54147     *:*
  UDP    q102exchange:ntp       *:*
  UDP    q102exchange:netbios-ns  *:*
  UDP    q102exchange:netbios-dgm  *:*

C:\Documents and Settings\webadmin>

Open in new window

Question by:jonathanduane2010
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
  • 2
LVL 76

Accepted Solution

Alan Hardisty earned 250 total points
ID: 35177034
Are the queues on your Exchange server full of messages your users didn't send?

If so - please have a read of my article:'t-send.html

Author Comment

ID: 35177043
cool, how do i find the sent messages on my exchange server?

Author Comment

ID: 35177052
ok am checking the queues now

Featured Post

Does Powershell have you tied up in knots?

Managing Active Directory does not always have to be complicated.  If you are spending more time trying instead of doing, then it's time to look at something else. For nearly 20 years, AD admins around the world have used one tool for day-to-day AD management: Hyena. Discover why

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

This article lists the top 5 free OST to PST Converter Tools. These tools save a lot of time for users when they want to convert OST to PST after their exchange server is no longer available or some other critical issue with exchange server or impor…
Read this checklist to learn more about the 15 things you should never include in an email signature.
In this Micro Video tutorial you will learn the basics about Database Availability Groups and How to configure one using a live Exchange Server Environment. The video tutorial explains the basics of the Exchange server Database Availability grou…
After creating this article (, I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…
Suggested Courses

623 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question